Privacy Policy — Tuppence
Last updated: 12 September 2026 · This is the privacy policy of the iOS app. For the website, see Privacy.
Overview
Tuppence («the App») is an expense tracker maintained by Simone Ruggiero. This policy explains how your information is handled when you use the App.
Data collection
The App does not collect, receive or store any personal data on our servers. There is no account and no sign-in. The only network requests the App makes are to Apple's own services and to RevenueCat, our subscription provider, both described below.
Everything you record — transactions, amounts, categories, budgets, recurring entries, notes and settings — is stored on your device, in the App's own database.
iCloud sync
The App synchronises your data through your own private iCloud database (CloudKit), so your entries and budgets are available on your other Apple devices. Some preferences, such as your currency, are synced through iCloud key-value storage. This happens between your device and your iCloud account: we have no access to that data and cannot read it. The processing is governed by the Apple Privacy Policy. If no iCloud account is configured, the data stays on the device.
Subscription management (RevenueCat)
Purchases are validated and kept in sync through RevenueCat, a subscription infrastructure provider. The App sends RevenueCat the App Store transaction receipt and a randomly generated identifier that is not linked to your name, email or Apple Account, and receives back whether Premium is active. RevenueCat also receives technical data sent by the SDK, such as the device model, the operating system version and the App version.
No transactions, amounts, categories or budgets — that is, none of the data you record in the App — are ever sent to RevenueCat or to anyone else. RevenueCat processes this data as our processor, under its Privacy Policy.
In-app purchases
The App offers auto-renewable subscriptions that unlock the Premium features; recording expenses stays free. Payments are processed by Apple through the App Store: we never see or store your payment information, and Apple gives us no personal data about the purchase.
Face ID and Touch ID
If you enable the app lock, the App asks the system to authenticate you with Face ID, Touch ID or your device passcode. The check is performed by iOS: the App only receives a success or failure result and never sees your biometric data.
Export, widgets, Siri and notifications
You can export your archive to a file: it is written where you choose through the system share sheet and never passes through us. Widgets and Siri shortcuts read data already on your device through a shared App Group, and nothing leaves the device for those features. Reminders are scheduled and shown locally.
What the App does not do
- No analytics, crash-reporting or usage-tracking SDKs
- No advertising identifiers and no cross-app tracking
- No bank connection: the App never asks for banking credentials and does not import transactions from any financial institution
- No selling or sharing of your data with third parties
Children's privacy
The App does not knowingly collect data from children under 13.
Changes
This policy may be updated over time. Changes are reflected in the date at the top of this page.
Contact
simone.ruggiero97@gmail.com — see also Support.